Privileged Identity Management
Also known as PIM
Making administrative roles available on request and for a limited time, rather than assigned permanently.
Instead of holding global administrator all day, an admin activates the role when needed, optionally with justification and approval, and it expires automatically. Most of the time the account carries no elevated rights at all.
That shrinks the window in which a compromised admin account is actually useful to an attacker, and produces a clean audit trail of who elevated, when, and why.
Where this comes up
Privileged Identity Management sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.